ATTACHMENT - can be made up of different filenames. It can use one of the following filenames or these filenames combined with domain names.
updated-password
email-password
new-password
password
approved-password
account-password
accepted-password
important-details
account-details
email-details
account-info
document
readme
account-report

The file extensions can be one of the following
.bat
.cmd
.exe
.pif
.scr
.zip

Technical Details

If the worm is executed it copies itself into the following location:
%sysdir%\nvhost.exe

It creates the following entries in the Windows Registry:
-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVers ion\Run
"Messenger Service" = "nvhost.exe"